ShinyHunters Claims Unprecedented FBI Hack, 2–3 TB of Data Allegedly Exfiltrated




ShinyHunters claimed that it breached the Federal Bureau of Investigation (FBI) and exfiltrated roughly 2 to 3 TB of data. The claim is significant, but there is an important qualification: as of the latest reporting, the FBI has not publicly confirmed the claimed compromise or the scope of the alleged data theft.

According to reporting published by The Register on September 22:

  1. Initial compromise: ShinyHunters says it exploited a previously unknown vulnerability in Oracle PeopleSoft exposed through the FBI's jobs website. The vulnerability allegedly provided remote code execution (RCE) on the affected servers.
  2. Website defacement: After obtaining access, the attackers reportedly defaced the FBI recruitment site with a message claiming the site had been seized by ShinyHunters. At the time of The Register's reporting, the FBI jobs site subsequently displayed a maintenance message.
  3. Lateral movement: The group claims it was able to move beyond the compromised recruitment infrastructure into FBI-managed systems hosted within AWS GovCloud. This is currently an attacker claim, not an independently verified finding.
  4. Large-scale exfiltration: ShinyHunters claims it downloaded approximately 2 to 3 TB of information concerning current employees, former employees and FBI job applicants.
  5. The group additionally claims that compromised FBI services included human resources, MedLink and Criminal Justice Information Services (CJIS). Those claims have not yet been independently confirmed.

Current assessment

Item
Current status
Threat actor
ShinyHunters claims responsibility
Target
FBI
Public disclosure
September 22, 2026
Claimed entry point
FBI jobs/recruitment infrastructure
Technology
Oracle PeopleSoft
Alleged technique
Pre-authentication RCE / zero-day
Alleged lateral movement
AWS GovCloud
Claimed theft
~2-3 TB
Claimed victims
Current/former FBI personnel + applicants
FBI confirmation
Not confirmed in the reporting available
Confidence in full attacker claims
Unverified / developing

An unusual motive

There's another interesting aspect to this incident.
ShinyHunters told The Register that the operation was not financially motivated and that it was not currently seeking a traditional extortion payment from the FBI. Instead, the group says it wants the FBI to retract or correct statements contained in an earlier FBI advisory about ShinyHunters.
That dispute relates to an FBI advisory issued on May 15, 2026.
In that advisory, the FBI described ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion. The bureau warned that actors using the ShinyHunters identity employ pressure tactics against victims and may make real or exaggerated claims concerning stolen sensitive information.
The FBI consequently advises treating claims from ShinyHunters with caution and recommends awaiting authoritative confirmation about what data was actually compromised following an intrusion.
That warning is particularly relevant here.

Why I would classify this as "Critical, but unconfirmed"

The 2-3 TB figure should not yet be presented as established fact.
There's a major difference between confirming:
FBIJobs infrastructure was compromised
and confirming:
ShinyHunters penetrated FBI GovCloud infrastructure and extracted several terabytes containing data on the FBI workforce and CJIS systems.
The second claim would represent a substantially greater security incident.
As of the latest reporting I found, The Register specifically states that the FBI had not responded to its request for comment. Oracle and AWS likewise had not responded to its questions concerning the claimed PeopleSoft vulnerability and alleged data access.
Therefore, for a threat-intelligence report I'd currently label this:
Severity: Critical
Confidence: Medium-Low / Developing
Attribution: ShinyHunters self-attribution
Data theft: Claimed, not yet independently verified

Defender implications

Gary, there's one part of this story I'd pay particular attention to given your systems/security role: PeopleSoft exposure.
If the reported intrusion vector proves accurate, the defensive lesson isn't limited to federal agencies. Internet-facing ERP, HR and applicant-tracking systems can hold extremely sensitive identities while simultaneously having connections into internal enterprise environments.
Organizations operating PeopleSoft should immediately prioritize:

1. Identify exposed PeopleSoft infrastructure

Inventory:
  • Internet-facing PeopleSoft systems
  • PeopleTools components
  • Reverse proxies publishing PeopleSoft
  • Applicant/recruitment portals
  • HR integrations
  • SSO connections
  • Service accounts
  • Cloud workloads reachable from these servers

2. Treat the application server as potentially compromised

Don't limit hunting to web logs.
Review for unusual:
PeopleSoft -> PowerShell
PeopleSoft -> cmd.exe
PeopleSoft -> scripting engine
Web server -> outbound connection
Application server -> unusual AWS/Azure access
Application identity -> HR/database access
Application server -> SMB/RDP/WinRM
If an Internet-facing application can execute code and its identity has access to downstream resources, exploitation can turn an application vulnerability into an identity and lateral-movement event.

Watch for secondary identity attacks

If personnel or applicant information was actually taken, the stolen information could potentially make subsequent spear-phishing or impersonation attacks considerably more convincing.
The FBI itself has previously warned that stolen sensitive enterprise information can be reused to construct sophisticated spear-phishing and impersonation campaigns.
That means defenders shouldn't consider this solely a PeopleSoft vulnerability issue. It potentially becomes an:
ERP → Identity → Cloud → Data exfiltration
incident chain.

One particularly important detail

This also appears to be different from the Florida DAVID incident involving ShinyHunters earlier this month.
In that case, Florida authorities confirmed unauthorized access to the state's DAVID driver database associated with compromised credentials belonging to a police department user. ShinyHunters had claimed access to multiple accounts, including an FBI agent's account, but that was an attack against Florida's driver database rather than a compromise of FBI infrastructure itself.

The September 22 FBI claim is therefore a separate and potentially much more significant incident.

Comments

Popular posts from this blog

Entire List Leaked for Canvas Ransomware Attack

OpenAI Discloses Emerging Risks in Autonomous AI Agent Behavior

WSUS CVE-2025-59287 Mitigation

Cloud Infrastructures are Having a Bad Week

CVE-2025-58034 Fortinet Warnings and Mitigation

Broadcom is dismantling of VMware Cloud Service Providers (VCSPs)

FBI Seizes RAMP Cybercrime Forum

Instagram Data Leak Update

CodeRED emergency alert system is currently down across many regions!